Description
OpenBMCS 2.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting arbitrary SQL code. Attackers can send GET requests to /debug/obix_test.php with malicious 'id' values to extract database information.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
2.4
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab, Semen 'samincube' Rozhkov @zeroscience
References
www.exploit-db.com/exploits/50668 (ExploitDB-50668)
www.openbmcs.com (Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5692.php (Zero Science Lab Disclosure (ZSL-2022-5692))
www.vulncheck.com/.../openbmcs-sql-injection-via-obixtestphp (VulnCheck Advisory: OpenBMCS SQL Injection via obix_test.php)